Privacy Management
Privacy Audits as a Control Instrument.
Regular privacy audits ensure the effectiveness of data protection measures and GDPR compliance.
Audit Fields
Data Processing Register
Completeness and correctness of the processing register per Art. 30 GDPR.
Data Subject Rights
Processes for exercising data subject rights per Art. 15-21 GDPR.
Data Processing Agreements
Completeness and correctness of DPAs with all processors per Art. 28 GDPR.
Technical and Organisational Measures
Implementation and effectiveness of TOMs per Art. 32 GDPR.
Data Breach Management
Processes for detecting, reporting and documenting data breaches per Art. 33-34 GDPR.
Privacy by Design and Default
Implementation of privacy-by-design and privacy-by-default principles for new processes and systems.
Audit Cycle
- Annual comprehensive privacy audit
- Quarterly review of processing register
- Ad-hoc audits after significant changes or data breaches
- Continuous monitoring of data subject request processing